
What if we taught a computer to discover and classify all the devices connected to the Internet, and to determine the most interesting targets, rather than using Shodan and specific keywords? This would give us a fairly good idea of the types of connected devices without needing keywords or precise data.
Cette présentation introduit les principaux concepts du Machine Learning dont notamment les jeux de données, l’apprentissage supervisé et non-supervisé, et vous montrera que créer un robot capable de scanner et cibler des équipements à partir de briques open-source est un jeu d’enfant. Les différentes phases de cette création seront abordées, codes sources à l’appui: collecte des données, pré-traitement, création des jeux de données, classification automatisée et post-traitement.
Finally, we will illustrate the effectiveness of this bot through several concrete examples and statistics from the scans and detections we carried out, to ultimately turn it into an intelligent (or almost) attack tool!
Virtualabs
Senior security researcher, Digital.Security
A senior security researcher and Head of Research and Development at Digital Security (Econocom), Virtualabs aka Damien Cauquil has been studying the security of connected devices and their ecosystem for several years. He has presented the results of his research at various specialised conferences such as the Chaos Communication Camp, the Chaos Communication Congress, La Nuit du Hack, Hack.lu, Hack in Paris and recently at the IoT Village during DEFCON 24.

